CWE-639: CWE-639
Yearly Trend
Top Affected Vendors
All CWE-639 CVEs (519)
This vulnerability allows attackers to bypass authorization controls in Saastech Cleaning and Internet Services Inc.'s TemizlikYolda software by manip...
Feb 11, 2026This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in Payload CMS where authenticated users from one authentication collectio...
Feb 6, 2026This vulnerability in the SupportCandy WordPress plugin allows authenticated attackers with subscriber-level access or higher to steal file attachment...
Jan 31, 2026This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the Mikado-Themes Dolcino WordPress theme. Attackers can bypass authori...
Jan 22, 2026This vulnerability allows attackers to bypass authorization controls in the Sweet Jane WordPress theme by manipulating user-controlled keys, enabling ...
Jan 22, 2026This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the Mikado-Themes Verdure WordPress theme. Attackers can bypass authori...
Jan 22, 2026This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the Mikado-Themes Fleur WordPress theme. It allows attackers to bypass ...
Jan 22, 2026This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the Holmes WordPress theme that allows attackers to bypass authorizatio...
Jan 22, 2026This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the Mikado-Themes Innovio WordPress theme. Attackers can bypass authori...
Jan 22, 2026This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the Overton WordPress theme by Mikado-Themes. It allows authenticated u...
Jan 22, 2026This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the Mikado-Themes Roam WordPress theme. Attackers can bypass authorizat...
Jan 22, 2026This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the Justicia WordPress theme by Mikado-Themes. It allows attackers to b...
Jan 22, 2026This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the Mikado-Themes Cocco WordPress theme that allows attackers to bypass...
Jan 22, 2026This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the Curly WordPress theme by Mikado-Themes. Attackers can bypass author...
Jan 22, 2026This vulnerability allows attackers to bypass authorization controls in the Fiorello WordPress theme by manipulating user-controlled keys, potentially...
Jan 22, 2026This vulnerability in the LearnPress WordPress plugin allows authenticated attackers with teacher-level access to delete arbitrary lesson material fil...
Jan 7, 2026This CVE describes an authorization bypass vulnerability in the Struktur WordPress theme, allowing attackers to access unauthorized data by manipulati...
Dec 30, 2025This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the Backpack Traveler WordPress theme that allows attackers to bypass a...
Dec 30, 2025This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the Mikado-Themes FiveStar WordPress theme. Attackers can bypass author...
Dec 30, 2025This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to read other users' order messages through the Return ...
Nov 21, 2025The Post Type Switcher WordPress plugin up to version 4.0.0 has an Insecure Direct Object Reference vulnerability that allows authenticated attackers ...
Nov 18, 2025This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in Alteryx Server where authenticated users can access other users' data b...
Nov 14, 2025This CVE describes an authorization bypass vulnerability in the Upcoming Events Lists WordPress plugin where attackers can manipulate object reference...
Sep 22, 2025This vulnerability allows attackers to bypass authorization controls by manipulating user-controlled keys, potentially accessing unauthorized data or ...
Aug 22, 2025This vulnerability in GLPI allows authenticated users to modify other users' reservations, potentially disrupting IT asset management and service desk...
Jul 30, 2025This vulnerability allows attackers to bypass authorization controls in JoomSky JS Job Manager by manipulating user-controlled keys, potentially acces...
Apr 1, 2025This vulnerability in Puma web server allows clients to override proxy-set headers like X-Forwarded-For by sending underscore versions (X-Forwarded_Fo...
Sep 19, 2024This vulnerability in the WP Extended WordPress plugin allows authenticated attackers with Contributor-level access or higher to duplicate posts creat...
Sep 4, 2024This vulnerability in IBM InfoSphere Information Server 11.7 allows authenticated users to bypass authorization controls and access or modify sensitiv...
Jun 30, 2024This vulnerability in the FileBird WordPress plugin allows authenticated attackers with author-level access or higher to delete folders created by oth...
May 2, 2024This vulnerability allows unauthenticated attackers to view private WordPress posts by exploiting an insecure direct object reference in the MP3 Audio...
Feb 19, 2026This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the Quiz And Survey Master WordPress plugin that allows attackers to by...
Feb 19, 2026This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the N-Media Frontend File Manager WordPress plugin. It allows attackers...
Feb 19, 2026Unauthenticated users can view completed guest orders by Order ID in Spree e-commerce platform, potentially exposing guest user PII including names, a...
Feb 6, 2026This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to change any user's profile picture or cover image, in...
Feb 5, 2026This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the Extensions For CF7 WordPress plugin. It allows attackers to bypass ...
Feb 3, 2026The WP ULike WordPress plugin has an Insecure Direct Object Reference vulnerability that allows authenticated attackers with Subscriber-level access o...
Feb 3, 2026This vulnerability allows authenticated WordPress users with Author-level permissions or higher to access, modify, and delete Document Library entries...
Jan 28, 2026This vulnerability allows attackers to bypass authorization controls in the MyD Delivery WordPress plugin by manipulating user-controlled keys, potent...
Dec 31, 2025This vulnerability allows attackers to bypass authorization controls in the Jewel Theme Master Addons for Elementor WordPress plugin by manipulating u...
Dec 31, 2025This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the wpDiscuz WordPress plugin that allows attackers to bypass authoriza...
Dec 30, 2025This vulnerability allows attackers to bypass authorization controls in the PickPlugins Post Grid and Gutenberg Blocks WordPress plugin by manipulatin...
Dec 18, 2025This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in Barn2 Plugins Document Library Lite WordPress plugin. Attackers can byp...
Dec 16, 2025The Campay Woocommerce Payment Gateway plugin for WordPress has a vulnerability that allows unauthenticated attackers to bypass payment processing and...
Dec 12, 2025This vulnerability allows attackers to bypass authorization controls in the Media Library Assistant WordPress plugin by manipulating user-controlled k...
Dec 9, 2025The QODE Wishlist for WooCommerce WordPress plugin has an Insecure Direct Object Reference vulnerability that allows unauthenticated attackers to modi...
Nov 27, 2025The WooCommerce OrderConvo plugin has an authorization bypass vulnerability that allows unauthenticated attackers to view sensitive order details and ...
Nov 25, 2025The YITH WooCommerce Wishlist plugin for WordPress has an Insecure Direct Object Reference vulnerability that allows unauthenticated attackers to disc...
Nov 19, 2025The Wisly WordPress plugin has an Insecure Direct Object Reference vulnerability that allows unauthenticated attackers to manipulate other users' wish...
Nov 11, 2025The WPFunnels WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to register user accounts even when sit...
Nov 8, 2025About CWE-639 (CWE-639)
Our database tracks 519 CVEs classified as CWE-639, with 63 rated critical and 165 rated high severity. The average CVSS score for CWE-639 vulnerabilities is 6.6.
External reference: View CWE-639 on MITRE CWE →
Monitor CWE-639 Vulnerabilities
Get alerted when new CWE-639 CVEs affect your infrastructure.
Start Monitoring Free